ThreatCluster

Hackers Exploit Microsoft Teams for Chaos Ransomware Attacks

First seen 30 Jul 2026, 13:40 UTC CybersecuritynewsGbhackers 81% similarity 67

Article Content

Browse articles
ThreatCluster

Hackers are impersonating IT helpdesk staff on Microsoft Teams to gain remote access to corporate networks, leading to the deployment of Chaos ransomware. This campaign, identified as STAC4749, has predominantly targeted North American organizations, with nearly 95% of attacks occurring in this region. The attackers use voice calls to convince employees to grant access, allowing them to install a custom post-exploitation toolchain. The campaign has been active from February to June 2026, affecting various sectors including services, manufacturing, energy, construction, and legal firms focused on intellectual property. Organizations are urged to enhance their security measures to prevent such social engineering tactics. Current mitigation strategies are not detailed, indicating a need for increased awareness and training among employees.

Key Points: • Hackers are using Microsoft Teams calls to impersonate IT support and gain access. • The Chaos ransomware campaign, tracked as STAC4749, primarily targets North American organizations. • Employees are persuaded to grant remote access, leading to widespread ransomware deployment.

ThreatCluster AI How this analysis works

Timeline

2026-02-01
STAC4749 campaign begins
Hackers start targeting North American organizations via Microsoft Teams impersonation.
Cybersecuritynews
2026-06-30
Campaign concludes
The Chaos ransomware campaign has been active for several months, affecting numerous organizations.
Cybersecuritynews
2026-07-30
Attack method reported
Hackers exploit Microsoft Teams to deploy Chaos ransomware, gaining access through social engineering.
Gbhackers

Community

Browse all →